Google Cloud Support roles and permissions

This page lists the IAM roles and permissions for Google Cloud Support. To search through all roles and permissions, see the role and permission index.

Google Cloud Support roles

Role Permissions

(roles/cloudsupport.admin)

Allows management of a support account without giving access to support cases. See the Cloud Support documentation for more information.

Lowest-level resources where you can grant this role:

  • Organization

cloudsupport.accounts.*

  • cloudsupport.accounts.create
  • cloudsupport.accounts.delete
  • cloudsupport.accounts.get
  • cloudsupport.accounts.getIamPolicy
  • cloudsupport.accounts.getUserRoles
  • cloudsupport.accounts.list
  • cloudsupport.accounts.purchase
  • cloudsupport.accounts.setIamPolicy
  • cloudsupport.accounts.update
  • cloudsupport.accounts.updateUserRoles

cloudsupport.operations.get

cloudsupport.properties.get

resourcemanager.organizations.get

(roles/cloudsupport.techSupportEditor)

Full read-write access to technical support cases (applicable for GCP Customer Care and Maps support). See the Cloud Support documentation for more information.

billing.resourceAssociations.list

cloudasset.assets.searchAllResources

cloudsupport.properties.get

cloudsupport.techCases.*

  • cloudsupport.techCases.create
  • cloudsupport.techCases.escalate
  • cloudsupport.techCases.get
  • cloudsupport.techCases.list
  • cloudsupport.techCases.update

resourcemanager.projects.get

resourcemanager.projects.list

(roles/cloudsupport.techSupportViewer)

Read-only access to technical support cases (applicable for GCP Customer Care and Maps support). See the Cloud Support documentation for more information.

cloudsupport.properties.get

cloudsupport.techCases.get

cloudsupport.techCases.list

resourcemanager.projects.get

resourcemanager.projects.list

(roles/cloudsupport.viewer)

Read-only access to details of a support account. This does not allow viewing cases. See the Cloud Support documentation for more information.

Lowest-level resources where you can grant this role:

  • Organization

cloudsupport.accounts.get

cloudsupport.accounts.getUserRoles

cloudsupport.accounts.list

cloudsupport.properties.get

Google Cloud Support permissions

Permission Included in roles

Owner (roles/owner)

Support Account Administrator (roles/cloudsupport.admin)

Owner (roles/owner)

Support Account Administrator (roles/cloudsupport.admin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Support Account Administrator (roles/cloudsupport.admin)

Support Account Viewer (roles/cloudsupport.viewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Support Account Administrator (roles/cloudsupport.admin)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Support Account Administrator (roles/cloudsupport.admin)

Support Account Viewer (roles/cloudsupport.viewer)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Support Account Administrator (roles/cloudsupport.admin)

Support Account Viewer (roles/cloudsupport.viewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Support Account Administrator (roles/cloudsupport.admin)

Owner (roles/owner)

Support Account Administrator (roles/cloudsupport.admin)

Security Admin (roles/iam.securityAdmin)

Owner (roles/owner)

Editor (roles/editor)

Support Account Administrator (roles/cloudsupport.admin)

Owner (roles/owner)

Editor (roles/editor)

Support Account Administrator (roles/cloudsupport.admin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Support Account Administrator (roles/cloudsupport.admin)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Billing Account Administrator (roles/billing.admin)

Cloud Hub Operator (roles/cloudhub.operator)

Support Account Administrator (roles/cloudsupport.admin)

Tech Support Editor (roles/cloudsupport.techSupportEditor)

Tech Support Viewer (roles/cloudsupport.techSupportViewer)

Support Account Viewer (roles/cloudsupport.viewer)

Owner (roles/owner)

Editor (roles/editor)

Billing Account Administrator (roles/billing.admin)

Tech Support Editor (roles/cloudsupport.techSupportEditor)

Owner (roles/owner)

Editor (roles/editor)

Billing Account Administrator (roles/billing.admin)

Tech Support Editor (roles/cloudsupport.techSupportEditor)

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Billing Account Administrator (roles/billing.admin)

Cloud Hub Operator (roles/cloudhub.operator)

Tech Support Editor (roles/cloudsupport.techSupportEditor)

Tech Support Viewer (roles/cloudsupport.techSupportViewer)

Service agent roles

Owner (roles/owner)

Editor (roles/editor)

Viewer (roles/viewer)

Billing Account Administrator (roles/billing.admin)

Cloud Hub Operator (roles/cloudhub.operator)

Tech Support Editor (roles/cloudsupport.techSupportEditor)

Tech Support Viewer (roles/cloudsupport.techSupportViewer)

Security Admin (roles/iam.securityAdmin)

Security Reviewer (roles/iam.securityReviewer)

Owner (roles/owner)

Editor (roles/editor)

Billing Account Administrator (roles/billing.admin)

Tech Support Editor (roles/cloudsupport.techSupportEditor)